Skip to content
Blog hero-min-1
16 September 2026

Inside a Global Phishing-as-a-Service Operation

Iron Man Unmasked: Inside the PhaaS Kit Behind a Global Phishing Wave

Author: Tadeáš Hájek, Whalebone Threat Intelligence Analyst

Since the beginning of 2026, Whalebone Threat Intelligence has tracked a large phishing wave targeting users around the world. At its peak, we observed hundreds of newly created phishing domains per day, impersonating couriers, government agencies, banks, telecommunications providers, and other services.

The activity was not the work of one group. It was supported by a broader criminal ecosystem visible across dozens of Telegram channels and organized around several phishing-as-a-service (PhaaS) kits, their developers and sellers, and the operators who deployed them.

By correlating distinctive patterns, template naming conventions, operator screenshots, and infrastructure pivots with material shared inside Chinese-speaking cybercrime communities, we linked the dominant activity with high confidence to a PhaaS product called Iron Man.

Countries in which we intercepted phishing websites utilizing the monitored PhaaS infrastructure (created via mapchart.net)

Key Findings

  • Hundreds of newly identified phishing domains appearing daily at peak activity, affecting targets globally.
  • Six technically distinct phishing kits following broadly similar workflows.
  • In the 3,596-domain categorized sample, failed-delivery lures were the largest category, followed by traffic fines, and rewards.
  • One kit – Iron Man – accounted for the majority of the activity observed by us.

 

Targeted sectors across 3,596 categorized phishing domains (a sample, not all domains observed)

 

For illustration, in the Czech Republic, we observed threat actors in quick succession impersonating government agencies, police, several courier companies, and a car parking operator. Together they deployed dozens of domains and targeted a pool of citizens large enough that the affected institutions and companies, as well as the news, publicly warned against them. This was just one country. Many (if not most) countries in Europe were affected at a similar scale.

Victim Journey Revisited

 

 

For readers who did not follow our earlier reporting, the following is a brief recap of the victim journey observed in these campaigns.

In most cases observed by us, victims received phishing links through RCS or iMessage rather than traditional SMS.

The phishing workflow was practically always the same: upon clicking on the phishing link, the victim was prompted to input personal data, followed by inputting payment card details, upon which they were prompted to proceed with MFA – either through their banking app, OTP, or any other predefined method.

The MFA capture step appeared to be human operator-dependent: personnel manually chose the MFA method displayed to the victim, depending on the victim's card settings, as they were either directly misusing the card for online payments or adding it into the attacker’s e-wallet.

Following the Trail to Chinese-Speaking PhaaS

The earlier research, as well as our own investigation in April, had already pointed toward a PhaaS kit likely developed by Chinese-speaking actors, hereafter referred to as Kit #1.

As the number of observed phishing sites grew, it became apparent that we were not looking at a single campaign or operator. Different backends, naming conventions, and technical fingerprints showed several distinct phishing kits being used.

Several clues suggested that at least part of this ecosystem was being developed and operated in Chinese-speaking communities. We observed simplified and traditional Chinese strings embedded in phishing code, while multiple kits contained Chinese workflow labels, runtime messages, and operator-facing instructions. Three captured victim-facing sites from Kit #1 also retained timestamps from the machines used to clone them, set to GMT+0800 (China Standard Time).

In nearly all instances, the actors utilized cheap TLDs and frequently utilized entire IPs for the phishing activities, with singular IPs frequently hosting dozens to hundreds of phishing domains. Many actors appeared to prefer hosting their infrastructure on Tencent (AS132203) or Alibaba (AS45102), however a smaller number also utilized other, smaller ASNs.

1-1

Kit #1 code snippets

3

Kit #1 with SingleFile fingerprint with timestamps

4-1

Kit #2 code snippets

5

Kit #3 code snippets

These technical clues gave us a direction for the next stage of the investigation: the Chinese-speaking cybercrime communities on Telegram.

We identified five Telegram channels promoting distinct phishing kits, while several additional products appeared in screenshots or were referenced by name. Products such as “Panda Shop”, “Shuishou/Sailors”, and “Chuanzhang/Captain” differed in branding, target focus, and implementation, but followed the same commercial model: ready-made phishing templates, simplified deployment, and operator-controlled victim workflows.

1-2

“Panda shop” PhaaS kit appearing in 2025. Silent since May 2026.

2-1

“Panda shop” control panel with manual MFA capture showcase.

3

“Panda shop” phishing templates for Spain.

4-2

“Shuishou/Sailors” control panel with manual MFA capture showcase.

5-2
 “Shuishou/Sailors” Telegram channel updates. 
6

“Chuanzhang/Captain” SSH installation panel, used to install the kit on a server.

7

“Chuanzhang/Captain” phishing site management, with some templates available.

Kit #1, which started our investigation in April, kept appearing far more frequently than other kits in the activity we observed.

Following Kit #1

We therefore began tracking Kit #1 more closely. Besides the code snippets and technical markers noted above, every instance of this kit we observed embedded a short, 10-letter random ID in the victim-facing backend paths (for instance /AbCdEfGhIj/api).

Examples of random 10 letter slugs

 

Another fingerprint of this kit was the template naming convention we observed on many domains. The template naming starts with an alphanumerical string, followed by country code, sector targeted, and the impersonated entity.

Examples of template naming observed

 

One cluster of Telegram channels that we reached was of particular interest, as we recognized the logo and naming from previous reporting by Group-IB on Haozi (耗子mouse)/Phoenix (不死鸟 businiao) kit.

This time, the kit is named Iron Man (钢铁侠 gangtiexia), yet the authors maintained the similarity in naming to the Phoenix iteration.

“bsn” and “busn” appear to reference businiao (不死鸟, Phoenix), using initials from its pinyin romanization

 

The developers also announced the change of naming together with their June promotion – 588 USDT (stablecoin referencing USD) for 3 months and one month for free.

Translated promotion and naming change announcement

 

The channels included detailed tutorials and showcases, among other things, alongside a community of sellers advertising the kit and operators sharing successful phishing campaigns to sell stolen personal data or associated services. These helped us to associate Iron Man with the phishing wave we were seeing.

Connecting Kit #1 to Iron Man

The 10-letter victim-side slug we noted above is unique for this kit – no other kit we observed was using it. The control panels are reached through a slug in exactly the same format, and several of those admin slugs turned up in the tutorials as well as in the operator community, eg:

 

 

Moreover, the template naming convention introduced above was observed both within the tutorials as well as within the larger ecosystem of users, showcasing their successful phishes, eg:

 

Some Iron Man operators, while showcasing their phishes, also displayed the domains, which included both the slugs and the template code. While the domains were not accessible at the time of our investigation, a pivot to the IP and URLscan open source database had us covered:

Operator “Lanmao”

Domain observed

Resolved IP

Another domain on the IP

43.162.114[.]28

 

Operator “Doudou”

Domain observed

Resolved IP

Another domain on the IP

49.51.186[.]91

 

Together, these technical and operational overlaps give us high confidence that Iron Man was the dominant kit behind the activity we tracked.

Inside the Iron Man Kit

Some content of the channels deserves additional attention, as it shows us how the kit works.

Setting up the phishing kit received particularly extensive coverage, providing new or prospective operators with detailed tutorials covering all steps from installation (utilizing SSH like the “Chuanzhang/Captain” kit), to setting up the control panel, and deploying the kit onto phishing domains.

Screenshot from installation tutorial video, bearing the previous “Phoenix” naming

 

Based on the observed tutorials, particular attention is being paid to avoiding detection, being referred to as 防红 (fanghong, “red-proofing”), likely in reference to preventing in-browser security warnings. A key pillar of “red-proofing” is a method observed in nearly all intercepted websites: the content never sits on the bare domain, but on a secondary URL path, most frequently /[country code]. Other methods include IP geofencing (a geographic boundary based on user IP addresses), and OS-based allowlists (meaning that only victims accessing from a given system will be let in).

“Red-proof” settings: phishing site entry point setting, IP geofencing and OS restrictions

 

The developers of Iron Man also shared a (slightly limited) demo version of the kit. The visuals are nearly identical to the Phoenix control panel previously reported and snapshotted in public sources, with the logo swapped and captcha added.

1-3
2-2
3-1
4-3

Finally, to illustrate the coverage of this phishing kit, a seller named “Jiatelin” shared the list of some available templates.

 

 

The Ecosystem

As already noted, every phishing kit was surrounded by its own community. The ecosystem surrounding Iron Man was the most extensive we observed, consisting predominantly of sellers advertising the kit by showcasing its functionality and operators sharing their successful phishing campaigns as well as reselling the stolen data or associated services.

Many operators advertised bulk SMS/RCS/iMessage sending services and demonstrated their delivery capabilities. For instance, the operator ‘ouni’ showcased successful phishing message delivery to recipients in the Czech Republic, as well as successful phishing attempts.

 

Message delivery showcase by the operator “ouni”

Successful phishes presented by the operator “ouni”

Operator “yachun” also showcased their smishing setups, consisting of a professional smishing farm with phones on racks, and a box of new SIM cards.

The last step for the cybercriminals is to misuse the stolen details. In the Telegram channels we have seen, cybercriminals showed a preference for e-wallets, predominantly Apple Pay. The stolen payment method can be added into the operator’s e-wallets as the victim inputs their details on the phishing site. Following the MFA capture, the card can be used until the victim or their bank kills it.

 

Conclusion

Iron Man shows why looking at individual phishing domains in isolation tells only part of the story. Domains, infrastructure, and operators may change quickly, but the platforms behind them leave recurring fingerprints.

By correlating those fingerprints across victim-facing phishing sites, infrastructure pivots, and material shared inside operator communities, we were able to connect activity that initially appeared fragmented to a single dominant PhaaS product. The investigation also showed that Iron Man does not operate in isolation: it sits within an ecosystem of developers, sellers, service providers, and operators who can combine different services to reproduce essentially the same phishing workflow at scale.

This modularity also makes the ecosystem resilient: disrupting one kit or provider may interrupt some operators, but alternative products and services allow others to migrate and continue. At the same time, ready-made kits, templates, and supporting services lower the technical barrier to entry, allowing less-skilled operators to run increasingly sophisticated phishing campaigns.

At Whalebone Threat Intelligence, this is why we monitor not only phishing domains, but also the kits, infrastructure, and operator ecosystems behind them. As those systems evolve, that visibility helps us adapt our detection and protection alongside them.